meeting-cleanup

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it is designed to process untrusted external content (meeting transcripts).
  • Ingestion points: Untrusted data enters the agent context through meeting transcripts uploaded by the user or fetched from external transcription tools.
  • Boundary markers: The instructions do not define clear delimiters or use 'ignore embedded instructions' warnings when processing the transcripts, which increases the risk of the agent obeying instructions hidden within the meeting notes.
  • Capability inventory: The skill has the capability to read sensitive internal files (PRDs, strategy documents, stakeholder profiles) located in the thoughts/shared/ directory. If MCP tools are active, it can also perform actions such as creating Linear tickets and posting to Slack.
  • Sanitization: There is no evidence of sanitization, validation, or filtering of the transcript content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 01:04 PM
Security Audit — agent-trust-hub — meeting-cleanup